8 July 2024

DoNex ransomware decryptor released


DoNex ransomware decryptor released

Researchers from cybersecurity firm Avast have uncovered a critical flaw in the cryptographic mechanism of the notorious DoNex ransomware and its predecessors. This discovery has allowed Avast, in collaboration with law enforcement organizations, to silently provide decryptors to victims of DoNex ransomware since March 2024.

The cryptographic weakness was publicly revealed at the Recon 2024 conference, Avast said, adding that it doesn’t have a reason to keep the flaw secret.

DoNex, which has undergone several rebrandings, first emerged under the name Muse in April 2022. Since then, the ransomware evolved through multiple iterations, including fake LockBit 3.0 and DarkTrace, culminating in the final version known as DoNex.

However, since April 2024, no new samples of DoNex have been detected, and its associated TOR site has been offline, indicating a potential halt in its evolution and operations. DoNex has been known for its targeted attacks, primarily affecting victims in the United States, Italy, and Belgium.

Back to the list

Latest Posts

Cyber Security Week in Review: October 4, 2024

Cyber Security Week in Review: October 4, 2024

In brief: the US disrupts FSB-linked ColdRiver hackers’ operations, Lockbit and EvilCorp members arrested, and more.
4 October 2024
Critical Ivanti EPM RCE flaw exploited in the wild

Critical Ivanti EPM RCE flaw exploited in the wild

The flaw is an SQL Injection issue that allows a remote attacker to execute arbitrary SQL queries in database.
3 October 2024
New China-aligned threat actor CeranaKeeper steals data from Southeast Asian entities

New China-aligned threat actor CeranaKeeper steals data from Southeast Asian entities

CeranaKeeper is notable for its evolving backdoor techniques, which allow it to evade detection and facilitate extensive data theft.
3 October 2024